<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get latest upload data.I am uploading csv file into splunk. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665862#M228459</link>
    <description>&lt;P&gt;Below is my CSV&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In this table when fist identify the Flow in our app we will update csv file with _key, App_name Date_find , Risk, and Status. when update happen the I will upload or ingest &amp;nbsp;the csv file into Splunk. almost real time. this csv we are keeping it as lookup outside Splunk. So nothing get deleted. when I ingest or upload all the pervious &amp;nbsp;entry get ingest in Splunk. only different is timestamp time at the ingestion. so all the entry such as _key 1 ,2, so get same timestamp. &amp;nbsp;I want to know if it possible to return the latest result only. so I will have all the data and not any duplicate. otherwise I need to find the different solution.&lt;BR /&gt;&lt;BR /&gt;Same thing happen when flow get fix Remediate_date, Risk_Afterremediate, and status get updated. file get ingested into Splunk.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;/P&gt;&lt;TABLE border="1" width="100.00016343340907%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;_key&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;App_name&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="47px"&gt;Date_find&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="47px"&gt;Status&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;Risk&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;Remediate_date&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;Risk_After remediate&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="47px"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;App1&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;12/04/2022&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Open&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Critical&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;12/10/2022&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Sustainable&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Closed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;App2&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;01/26/2023&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Open&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Moderate&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;02/12/2023&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Sustainable&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Close&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Mon, 23 Oct 2023 14:40:05 GMT</pubDate>
    <dc:creator>abi2023</dc:creator>
    <dc:date>2023-10-23T14:40:05Z</dc:date>
    <item>
      <title>How to get latest upload data.I am uploading csv file into splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665714#M228393</link>
      <description>&lt;P&gt;I am uploading csv file format data into splunk. every time I make change to the data or add any info I will update the full csv file into splunk.&amp;nbsp;&lt;BR /&gt;now I have duplicate event in splunk.&amp;nbsp;&lt;BR /&gt;Is it possible to sort by only last upload csv file data show?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 18:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665714#M228393</guid>
      <dc:creator>abi2023</dc:creator>
      <dc:date>2023-10-20T18:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to get latest upload data.I am uploading csv file into splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665715#M228394</link>
      <description>&lt;P&gt;No. If you upload a file via "add data" screen, the events are getting indexed and are immutable. There is no such thing as "updating" the events.&lt;/P&gt;&lt;P&gt;Also, why would you upload the same csv multiple times? Why would you even upload csv at all? In normal production environment you typically monitor log files or get events ingested in a different continuous way. Sometimes you upload samples of logs into dev/testing environments but that's a different case and there you usually don't mind the duplicates and/or you'd simply delete and recreate the index if duplication was an issue for you.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 20:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665715#M228394</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-20T20:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to get latest upload data.I am uploading csv file into splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665747#M228411</link>
      <description>&lt;P&gt;Not completely impossible. &amp;nbsp;But before discussing workarounds, I have the same question as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;does: Why? &amp;nbsp;Are they the same events (with the same timestamp, etc.)? &amp;nbsp;Does the CSV even represent time series events? &amp;nbsp;If they are the same events but with updates, why not delete previously loaded events before upload? &amp;nbsp;I use CSV upload regularly. &amp;nbsp;Each contains different events. &amp;nbsp;Even so, I name files differently in part for peace of mind.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2023 10:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665747#M228411</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-10-21T10:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to get latest upload data.I am uploading csv file into splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665862#M228459</link>
      <description>&lt;P&gt;Below is my CSV&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In this table when fist identify the Flow in our app we will update csv file with _key, App_name Date_find , Risk, and Status. when update happen the I will upload or ingest &amp;nbsp;the csv file into Splunk. almost real time. this csv we are keeping it as lookup outside Splunk. So nothing get deleted. when I ingest or upload all the pervious &amp;nbsp;entry get ingest in Splunk. only different is timestamp time at the ingestion. so all the entry such as _key 1 ,2, so get same timestamp. &amp;nbsp;I want to know if it possible to return the latest result only. so I will have all the data and not any duplicate. otherwise I need to find the different solution.&lt;BR /&gt;&lt;BR /&gt;Same thing happen when flow get fix Remediate_date, Risk_Afterremediate, and status get updated. file get ingested into Splunk.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;/P&gt;&lt;TABLE border="1" width="100.00016343340907%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;_key&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;App_name&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="47px"&gt;Date_find&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="47px"&gt;Status&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;Risk&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;Remediate_date&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;Risk_After remediate&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="47px"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;App1&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;12/04/2022&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Open&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Critical&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;12/10/2022&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Sustainable&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Closed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;App2&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;01/26/2023&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Open&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Moderate&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;02/12/2023&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Sustainable&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;Close&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 23 Oct 2023 14:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665862#M228459</guid>
      <dc:creator>abi2023</dc:creator>
      <dc:date>2023-10-23T14:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get latest upload data.I am uploading csv file into splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665863#M228460</link>
      <description>&lt;P&gt;Sure. That's what stats first/last/earliest/latest/index_earliest/index_latest are for.&lt;/P&gt;&lt;P&gt;But:&lt;/P&gt;&lt;P&gt;1) Aren't you trying to do in Splunk something it's not supposed to be? (like a database table)&lt;/P&gt;&lt;P&gt;2) Why not use a lookup instead of ingesting events?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 14:51:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665863#M228460</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-23T14:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to get latest upload data.I am uploading csv file into splunk.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665963#M228472</link>
      <description>&lt;P&gt;You still need to explain your use case in Splunk. &amp;nbsp;As I said, I use CSV update regularly; in fact, my CSV files have a similar structure. &amp;nbsp;In my case, I have two timestamps of particular interest, "First Detected" and "Last Detected", both of them similar to "Date_Find" in your example. &amp;nbsp;But "Last Detected" changes in every scan. &amp;nbsp;So, I use this field as _time when I ingest.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What do you use as _time? &amp;nbsp;Do you have a field that changes every time?&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If you do not select a field in the CSV as _time, Splunk will use the time of your upload as _time. &amp;nbsp;Will that serve your purpose?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If there is no value of _time that make sense in your data, can you just use file name to determine which is the latest? (To exemplify, there are lots of data inconsistence in my CSV files. &amp;nbsp;So in some searches I simply rely on file name - which translates into source field.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 24 Oct 2023 03:54:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-latest-upload-data-I-am-uploading-csv-file-into/m-p/665963#M228472</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-10-24T03:54:22Z</dc:date>
    </item>
  </channel>
</rss>

